Experts Find Flaw in Replicate AI Service Exposing Customers' Models and Data
ID: f8dd6795-4fd6-51dd-990e-b701fddceb80
STIX ID: report--f8dd6795-4fd6-51dd-990e-b701fddceb80
Feed Name: The Hacker News
Threat Score
Researchers disclosed a critical flaw in AI-as-a-service provider Replicate in which malicious models packaged via the Cog tool could achieve remote code execution and abuse a centralized Redis queue to perform cross-tenant attacks, potentially exposing private models, prompts, and PII; Wiz demonstrated the technique, Replicate patched the issue after responsible disclosure in January 2024, and there is no evidence of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
